CVE-2021-31850

Published Dec 8, 2021

Last updated a year ago

Overview

Description
A denial-of-service vulnerability in Database Security (DBS) prior to 4.8.4 allows a remote authenticated administrator to trigger a denial-of-service attack against the DBS server. The configuration of Archiving through the User interface incorrectly allowed the creation of directories and files in Windows system directories and other locations where sensitive data could be overwritten. The former could lead to a DoS, whilst the latter could lead to data destruction on the DBS server.
Source
trellixpsirt@trellix.com
NVD status
Modified

Risk scores

CVSS 3.1

Type
Primary
Base score
6.1
Impact score
5.2
Exploitability score
0.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:H
Severity
MEDIUM

CVSS 2.0

Type
Primary
Base score
4.9
Impact score
4.9
Exploitability score
6.8
Vector string
AV:N/AC:M/Au:S/C:N/I:P/A:P

Weaknesses

nvd@nist.gov
CWE-552
trellixpsirt@trellix.com
CWE-552

Social media

Hype score
Not currently trending

Configurations